<?php
require_once('../safe.php');
?>
<?php
$action=$_GET["action"];
$id=intval($_GET["id"]);
if(isset($_POST['id'])){$ID_Dele=implode(",",$_POST['id']);}
$title=$_POST["title"];
$content=$_POST["content"];
$ntype=$_POST["ntype"];
if($action=='add'){
$sql = "INSERT INTO ph_notice(title,content,cdate,ntype)VALUES('".$title."','".$content."','".date("Y-m-d",time())."','".$ntype."')";
mysqli_query($conn,$sql);
echo "<script language=JavaScript>\r\n";
echo "location.href='list.php'\r\n";
echo "</script>";
}
if($action=='edit'){
$sql = "update ph_notice set title='".$title."',content='".$content."',ntype='".$ntype."' where id='".$id."'";
mysqli_query($conn,$sql);
echo "<script language=JavaScript>\r\n";
echo "location.href='list.php'\r\n";
echo "</script>";
}
if($action=='del'){
if($ID_Dele<>''){
$sql = "delete from ph_notice where id in(".$ID_Dele.")";
mysqli_query($conn,$sql);}
if($id<>''){
$sql = "delete from ph_notice where id ='".$id."'";
mysqli_query($conn,$sql);}
echo "<script language=JavaScript>\r\n";
echo "location.href='list.php'\r\n";
echo "</script>";
}
?>